Описание
GoCast OS Command Injection vulnerability
An OS command injection vulnerability exists in the name parameter of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.
Пакеты
Наименование
github.com/mayuresh82/gocast
go
Затронутые версииВерсия исправления
<= 1.1.3
Отсутствует
Связанные уязвимости
CVSS3: 9.8
nvd
около 1 года назад
An OS command injection vulnerability exists in the name parameter of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.